Identity Management System for Secure Attribute Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face challenges in securely managing multiple identities and information disclosure when transacting online, as they often struggle to determine what information is shared with websites and whether those sites are legitimate, leading to increased risks of identity theft and data breaches.

Innovation Solution

A method and system for integrating multiple identities and identity providers, which involves receiving a service provider's security policy, determining requested attributes, obtaining authenticated attributes from a trusted issuer, registering with a provisioning service, and accessing services based on these attributes, allowing users to control information dissemination and enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users disclose personal information to multiple websites for online transactions, then transaction convenience and comfort level increase, but the risk of identity theft and information theft increases

Engineering Contradiction:
Improvetransaction convenienceVSAvoididentity theft risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments personal information into distinct attributes (name, address, social security number, account numbers, credit card numbers, etc.) and organizes them into structured identity profiles. This segmentation allows users to selectively disclose only necessary attributes to specific websites rather than disclosing all personal information, thereby maintaining transaction convenience while reducing identity theft risk.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary identity management system that acts as a mediator between users and websites. This system verifies website legitimacy, manages attribute assertions, and controls information flow. The intermediary prevents users from directly disclosing sensitive information to potentially fraudulent sites while enabling secure transactions with legitimate services.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If users transact with many different websites and user interfaces, then transaction variety and service access increase, but the ability to determine information disclosure and website legitimacy decreases

Engineering Contradiction:
Improveservice access varietyVSAvoidwebsite legitimacy verification
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent creates a universal identity management framework that works across multiple websites and services. The system provides consistent functionality for attribute assertion, website verification, and information disclosure control regardless of which service provider is accessed. This universal approach enables users to transact with diverse services while maintaining consistent security and verification capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements feedback mechanisms where the identity management system continuously verifies website legitimacy through multiple checks and provides users with visibility into what information is being disclosed and to whom. The system feeds back confirmation of website authenticity and attribute assertion status to users, enabling informed decisions about information disclosure across different services.

Inventive Principle:
Principle #23Feedback

3Reliability

If users are requested to reveal personal information for security verification, then transaction security improves, but the exposure to imitators stealing identity and money increases

Engineering Contradiction:
Improvetransaction securityVSAvoidpersonal information exposure
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies partial action by requiring users to disclose only the specific attributes necessary for verifying transaction security rather than all personal information. The system determines the minimum necessary attribute set for each transaction type and requests only those specific pieces of information, thereby maintaining security verification while minimizing information exposure to imitators.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent performs preliminary verification of website legitimacy and user identity through the intermediary system before transactions occur. The identity management system pre-authenticates users and pre-verifies website credentials, establishing security credentials in advance. This preliminary action ensures transaction security is established before any sensitive information is exchanged, preventing imitators from obtaining personal information under false pretenses.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7788729B2Method and system for integrating multiple identities, identity mechanisms and identity providers in a single user paradigm
Publication Date: 2010.08.31 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7788729B2 patent drawing
  • US7788729B2 patent drawing
  • US7788729B2 patent drawing

AI summary

Exemplary embodiments disclosed herein may include a method and system for integrating multiple identities and identity providers, including, receiving the security policy of a service provider, determining the attributes requested by the service provider, obtaining authenticated attributes requested by the service provider, registering with a provisioning service based at least in part upon the authenticated attributes, and accessing services of the service provider based at least in part upon the registration from the provisioning service.